Context 154 - May 2018

48 C O N T E X T 1 5 4 : M A Y 2 0 1 8 Director’s cut Some data protection prompts from the IHBC The new General Data Protection Regulation (GDPR) legislation seems at first sight to be one of the major changes in data management issues in recent years, covering issues relating to data management and protection. It has presented the IHBC – and most other organisations, regardless of size – with some serious challenges, even if we can easily accept that the principles around the need for data care are laudable and, indeed, essential. For example, the recent case where Cambridge Analytica has been accused of mining data from a free Facebook app in a way that might have swayed a UK plebiscite and a US election indicates just how important data management is for everyone. In light of the changes in both law and sentiment, the IHBC has had a close look at its own operations. A review of our own approach may be useful to others. For us, taking a positive perspective on the more daunting implications of the legislation as a whole – not just GDPR specifically, but data protection generally – means recognising, first, that data gatherers and holders (‘controllers’) and users (‘processors’) must formally ‘think through’ why and how they are using personal data, and not just act without structured consideration. Their operations must be reasonable, non-invasive and legitimate. Most requirements are simply sensible, and so may not mean a huge adjustment for many historically conscientious users, but it does at the very least require a structured, informed approach to data in their care. In this sense, data care is a bit like care in conservation and heritage: a sensible listed building owner might do the right thing by their historic building without a great deal of thinking because much of what is right is also sensible. That is not to say that all people are sensible, or even that the sensible ones will always get the right advice or even do the right thing. So, requiring people to make the effort to think about their actions and decisions regarding what they do with resources under their control – including securing advice on actions as and when they need it – is a good thing, whether that principle is applied to buildings or to data. Being required to make the effort to think through the issues in a structured way (as listed building legislation does, as much as GDPR) makes the outcome more secure. And the bandits and charlatans find life a little less easy, which is certainly all for the good. The first point for GDPR, as the IHBC is approaching it, is that the legislation is a refinement and extension of existing (and, again, often common sense) approaches to data management. This includes preceding legislation, notably the Data Protection Act 1998 (DPA), as discussed further below, which, as its guidance notes, is ‘based around eight principles of good information handling’. GDPR itself also continues a sensible proportionality, recognising the scale and interest of the responsible body while also offering guidance tailored to small organisations such as ours. Perhaps more important, from the IHBC’s perspective, is our good fortune in having been able to apply common-sense approaches to our data management historically, as data- related considerations often require access to technical support and related data systems, all integrated with the accessible language and protocols that the GDPR also promotes. That capacity has long been available across the IHBC’s close national office and IT consultancy network – including, especially, our staff, administration, membership management and uniquely supportive technical advisers. So as the IHBC has already been well advised and supported in these matters, our review of the changes under the new legislation suggests that – not least compared to many organisations – the implications are neither unmanageably substantial nor technically daunting. As regards the legislation itself, anyone who holds (that is, ‘has control’ of) personal data, or manipulates or uses that data (that is, ‘processes’ it) needs to be clear on the legitimate and lawful reasons underpinning their operations. People can still work with data where it is reasonable and ‘necessary’, but they need to be clear about the justification for what they do and how they hold the data. They need to be sure that – under the headline terms of the GDPR – their care and use of that data complies with the new law. There are different ways to justify how data is cared for and handled under the GDPR, including addressing contractual agreements, getting consent specific to the data and its use, and the broader brush of ‘legitimate interest’. Guidance is clear that data processing organisations must be cautious in adopting the ‘legitimate interest’ route to justify their data processing, as they ‘are taking on extra responsibility for considering and protecting people’s rights and interests’. However, the IHBC is already registered formally as a data ‘controller’ – actually one of only five ‘institutes’ of the half million or so organisations currently registered as controllers – so that hurdle has already been crossed. And as built and historic environment conservation

RkJQdWJsaXNoZXIy MjgyMjA=